Skip to content

CS Professional · Compliance Management, Audit and Due Diligence · Audit Process and Documentation

While auditing Kaveri Textiles Ltd, the auditor finds that management has no documented process for identifying business risks relevant to financial reporting; risks are handled ad hoc as they arise. As per SA 315, what should the auditor do first?

The auditor should first discuss with management whether business risks relevant to financial reporting have been identified and how they were addressed. Afterwards, the auditor evaluates whether the lack of a documented process is appropriate or a significant deficiency; it is not automatically one.

  1. ADiscuss with management whether business risks relevant to financial reporting have been identified and how they have been addressedCorrect
  2. BWithdraw from the engagement because the absence of a process is always a significant deficiency
  3. CIgnore the matter because a risk assessment process is the auditor's responsibility alone
  4. DIssue an adverse opinion on the financial statements immediately

Explanation

Where the entity has no risk assessment process or only an ad hoc one, the auditor discusses with management whether business risks relevant to financial reporting were identified and how they were addressed. The auditor then evaluates whether the absence of a documented process is appropriate in the circumstances or is a significant deficiency. It is not automatically a significant deficiency, so withdrawal or an adverse opinion is not the first step.

Did you get it right without looking?

One question tells you little. A timed set on Audit Process and Documentation shows your real accuracy, how long you take and where you lose marks.

More Audit Process and Documentation questions